C2y Draft Removes 45 Undefined Behaviors from C
Reducing undefined behavior in the C language
At Kernel Recipes, Martin Uecker explained why undefined behavior in C lets compilers do anything—even invoke nasal demons—and how the C committee is fighting back. The in-progress C2y draft has already removed 45 of roughly 100 undefined behaviors, while better warnings, sanitizers, and tools like Fil-C and CHERI chip away at memory-safety bugs. Full memory safety may require a restricted language plus formal verification, but C is still alive and improving.
The problem, Uecker said, is that the standard allows a compiler to do anything in response to undefined behavior, up to the point of invoking nasal demons.
- pizlonator
It’s cool that this mentions Fil-C but it also undersells it. TFA also undersells CHERI. Fil-C doesn’t just “find a lot of temporal-safety” bugs. It closes off memory safety bugs (special and temporal) for exploit writers and ascribes a tight semantics to the whole language. CHERI makes some different trade offs but also gives a tight enough semantics that memory safety exploits aren’t going to work. Both CHERI and Fil-C are more comprehensive than Rust, since they attack the problem at the ABI level (and so you don’t get the problem that the protection only applies to the parts that were rewritten in the safe subset of a new language). Rust could be claimed to be better in that its compile time, but that doesn’t make a significant difference if you’re worried about the definedness of semantics or exploitability.
- chasil
"Some Honeywell machines, for example, had nine-bit bytes."
OS 2200 has 36-bit words. It is still a supported platform.
https://en.wikipedia.org/wiki/UNIVAC_1100/2200_series
This platform was the first SMP UNIX implementation:
"Any configuration supplied by Sperry, including multiprocessor ones, can run the UNIX system."
https://www.nokia.com/bell-labs/about/dennis-m-ritchie/other...
- vrighter
i was actually thinking of starting a joke project which would make UB actually UB. not the sort of "in practice signed overflow is all done the same by most modern cpus". i mean an RNG and a compiler plugin system for introducing new Bs to go with the Us
- hn_submit
I believe this is barking up the wrong tree since IMHO C is just "high level assembly" for systems programming. As soon as you add runtime behavior to combat Undefined Behavior (UB) you're blowing up execution times. And static analysis can only go so far without blowing up compile times.
C is "the right tool for the right job" which is operating systems and its code which is called thousands of times per second. You cannot afford even one iota of runtime checks in that code. The developer must know what he's doing or he should get out of the kitchen.
We should discourage the usage of C in application programming and prod application developers towards memory safe languages like Rust or Go.
And I'm not even sure if Rust solves this case as far as UB is concerned.
- vbezhenar
My main issue with UB in C is that it's silent.
I'm OK with compiler doing wild thing, OK, whatever. Well, I'm not OK but I can accept it in this crazy world.
But I want to have loud warnings! Like WARNING: this conditional operator has been collapsed to one branch because earlier division by zero is UB. And now I can notice it and rewrite it or just remove that condition.
I understand that this code can be result of macro expansion. That's OK. Macros should either include some pragmas to temporary disable specific diagnostics or user should surround macro usage with these pragmas, if they can't edit the macro. It's already happening with other warnings.
Or maybe compiler could be smart enough to distinguish macro expansion from honest user mistake, I don't know.
I remember when C++ compiler just removed function epilogue where I wrote simple infinite loop. That was so crazy. So instead of entering the infinite loop, my program just continued to execute the function that happened to be linked below. Imagine debugging that. Zero diagnostics.
- rwmj
I think https://en.wikipedia.org/wiki/CompCert should at least be mentioned, even though it's not free software ("source available" license). It's the actual way that companies that have large C code bases in safety-critical industries verify their code.
- 1vuio0pswjnm7
1790620504 | Reducing undefined behavior in the C language | https://lwn.net/SubscriberLink/1095811/b9325731ea9b61e0/ | https://news.ycombinator.com/item?id=49882419 | 15 comments
1790673092 | Reducing undefined behavior in the C language | https://lwn.net/SubscriberLink/1095811/efcdbcf080cfa4c6/ | https://news.ycombinator.com/item?id=49890290 | 0 comments
- p1necone
The concept of undefined behaviour specific to C/C++ has always seemed batshit insane to me, and I'm yet to read anything about it that has made it seem any less so.